Digital archive encryption system

The file encryption system, which uses multi-level account password authentication and cloud gateway architecture, solves the security and efficiency problems in enterprise file management and achieves efficient access control and secure data transmission.

CN121664460APending Publication Date: 2026-03-13ZHONGDUN INNOVATIVE DIGITAL TECH (BEIJING) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-11
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

Existing enterprise file management systems suffer from risks of personal privacy data leakage, easily cracked encryption methods, low efficiency of manual review, and inconvenience of online browsing, resulting in insufficient security and management efficiency.

Method used

It adopts a multi-level account password authentication and cloud gateway architecture, and realizes encrypted management and access control of file data through the interaction between enterprise servers, cloud gateways and local terminals, providing multi-level security verification and online browsing options.

Benefits of technology

It improves the security and management efficiency of archival data, reduces server load, ensures data transmission speed, and provides different services under different permissions, supports online browsing and downloading, and facilitates post-event retrieval.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121664460A_ABST
    Figure CN121664460A_ABST
Patent Text Reader

Abstract

The invention relates to a digital archive encryption system, which can provide multi-level account password authentication for a terminal in an enterprise internal server, enhance the security of archive management, can improve the data transmission speed by adopting a cloud gateway architecture, and interacts with a local terminal based on a cloud gateway and an enterprise server, thereby improving the security of archive management. Multi-level management can be formed, and fault positions can be inquired conveniently; and the file can be fed back instead of prompting information under the condition that the password is incorrect, so that the user can know which password is wrong after viewing the file, and the working attitude of the employee can be investigated to a certain extent.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data transmission, and more specifically to a digital archive encryption system. Background Technology

[0002] Current enterprise service application systems typically include a file system to store various information about employees within the company. Although this information is usually only accessible to personnel in specific positions, and individuals can only access their own file information, there is still a risk of leakage of personal privacy data, and it is difficult to hold anyone accountable.

[0003] Current security management of archival data is usually quite simple and direct, involving only identity verification of login personnel. Once identity verification is successful, they can log in to the system and view relevant archival data. This method has poor security. If the account of a specific person is leaked, other people who have access to the account information can obtain a large amount of employee archival data.

[0004] Meanwhile, in order to facilitate the management of employee file data, the current file data is usually stored in the same folder or multiple folders with a uniform format. In this case, some companies will encrypt the folders. However, this type of encryption still poses a risk that the employee file data can be obtained in batches after the folder encryption is cracked.

[0005] Another method for protecting archival data is to provide only online browsing functionality and not download functionality. However, this method can lead to inconvenience in many situations, such as employees having to rewrite their own records when they need the information, or other managers having to view the records on the company's local terminal when they need the data.

[0006] Currently, the safest way to manage archival data is still through manual review and online provision of relevant archival data, but this method wastes human resources and is inefficient.

[0007] Therefore, there is an urgent need for a digital archive encryption system that can effectively provide and manage personal file information without the need for bulk downloading of employee files within an enterprise, and improve the security of personal file data management without manual review. Summary of the Invention

[0008] To address the problems of the existing technology, this invention provides a digital archive encryption system that can provide multi-level account and password authentication from the enterprise's internal server to the terminal, thereby enhancing the security of archive management. At the same time, the cloud gateway architecture can improve data transmission speed, and the interaction between the cloud gateway and the enterprise server with the local terminal can form a multi-level management system, facilitating fault retrieval.

[0009] The technical solution adopted in this invention is as follows: A digital archive encryption system, the system being capable of performing the following steps: S1. The local terminal sends a data request to the remote server via the cloud gateway; S2. Based on the data request, the server locates the folder where the data request is stored and determines whether the folder containing the file is an encrypted folder; S21. If the folder is an encrypted folder, the password M1 input interface is sent back to the local terminal via the cloud gateway, and step S3 is executed; S22. If the folder is an unencrypted folder, then traverse the folder, confirm the identifiers of each encrypted file and each unencrypted file, and execute step S4; S3. The server determines whether the password M1 is correct based on the password M1 fed back by the local terminal; S31. If the password M1 is incorrect, the requested data will not be provided to the user; S32. If the password M2 is correct, then traverse the folder, confirm the identifiers of each encrypted file and each unencrypted file, and execute step S4; S4. The server sends a file type confirmation input interface to the local terminal; S5. The server sends the file requested by the local terminal to the cloud gateway; S6. The cloud gateway sends a file browsing mode selection interface to the local terminal; S7. The local terminal display device displays the file.

[0010] Furthermore, the folder stores multiple archive files, which are encrypted and / or unencrypted files.

[0011] Further, S41. Obtain the file type selection result sent by the local terminal, and based on the encrypted file identifiers and unencrypted file identifiers obtained in step S32 or step S22, determine whether the local terminal correctly responded to the requested file type.

[0012] Furthermore, the local terminal reports two file types: encrypted archive files and unencrypted archive files.

[0013] Further, S42. If the file type returned by the local terminal is the same as the file type corresponding to the file identifier obtained by the server, and the file type is an encrypted archive file; then send a password M2 input interface to the local terminal.

[0014] Furthermore, S43. If the password M2 is incorrect, the server generates a garbled file and then directly sends the garbled file back to the local terminal.

[0015] Further, S44. If the password M2 is correct, then proceed to step S5.

[0016] Further, S45. If the file type returned by the local terminal is the same as the file type corresponding to the file identifier obtained by the server, and the file type is an unencrypted archive file; then step S5 is executed.

[0017] Furthermore, the server is an enterprise server.

[0018] Further, S46. If the file type returned by the local terminal is different from the file type corresponding to the file identifier obtained by the server, then an empty file is returned to the local terminal.

[0019] The present invention has the following beneficial effects: 1) It can provide multi-level account and password authentication from the enterprise's internal server to the terminal, which can enhance the security of file management. At the same time, the cloud gateway architecture can improve the data transmission speed, and the interaction between the cloud gateway and the enterprise server with the local terminal can form a multi-level management system, which facilitates troubleshooting.

[0020] 2) By setting up an architecture of enterprise server, cloud gateway and local terminal, the enterprise server and cloud gateway can interact with the local terminal at different stages of the file data request process. The cloud gateway can determine the permissions of the requester when forwarding request data, so as to provide different services based on different permissions. This can reduce the server load to a certain extent, ensure the security of file data and improve the system's work efficiency.

[0021] 3) Through the S4 configuration, the enterprise server can provide different files to the local terminal after determining whether the security verification at different levels is accurate. Specifically: if the file type returned by the local terminal is different from the file type corresponding to the file identifier obtained by the server, then an empty file is returned to the local terminal; if the password M2 is incorrect, then the server generates a garbled file and directly returns the garbled file to the local terminal. This method allows users or administrators to clearly identify at which level of security verification the problem occurred after seeing the file returned by the enterprise server and considering whether the enterprise server returned a file.

[0022] 4) By encrypting the folders storing archive data, encrypting only some archive files, and having the enterprise server and cloud gateway query the local terminal respectively, the security of archive data can be greatly improved. Furthermore, setting up online browsing and record download methods can effectively perform post-event statistics and queries.

[0023] 5) The present invention sets up a four-level security authentication to improve security. In the two-level security authentication process, even if the authentication fails, the enterprise server still provides the file to the local terminal. If the employee sends or uses the file without opening it, the other end can find out that the employee has not viewed or verified the downloaded data, which can assess the employee's work attitude to a certain extent. Attached Figure Description

[0024] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0025] Figure 1 This is a workflow diagram of a digital archive encryption system. Detailed Implementation

[0026] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of this application, including various details to aid understanding. These should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this application. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0027] To enable those skilled in the art to better understand the present invention, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are merely some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort should fall within the scope of protection of the present invention.

[0028] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of this application, including various details to aid understanding. These should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this application. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0029] like Figure 1 As shown, a digital archive encryption system is capable of performing the following steps: S1. The local terminal sends a data request to the remote server via the cloud gateway; The cloud gateway queries the permission information of the employee corresponding to the local terminal. If the employee has the highest level of access, then when forwarding the data request to the server, an accessibility message will be included. If the employee's permission is intermediate, then check if the employee has authorization information for the highest permission. If the employee has authorization information for the highest permission, then process according to the highest permission. If the employee does not have authorization information for the highest permission, then execute step S2. If the employee's permissions are basic, then step S2 is executed, and after receiving the requested file in step S5, the cloud gateway does not send a file browsing mode selection interface to the local terminal, but only provides online browsing functionality.

[0030] S2. Based on the data request, the server locates the folder where the data request is stored and determines whether the folder containing the file is an encrypted folder; S21. If the folder is an encrypted folder, the password M1 input interface is sent back to the local terminal via the cloud gateway, and step S3 is executed; S22. If the folder is an unencrypted folder, then traverse the folder, confirm the identifiers of each encrypted file and each unencrypted file, and execute step S4; S3. The server determines whether the password M1 is correct based on the password M1 fed back by the local terminal; S31. If the password M1 is incorrect, the requested data will not be provided to the user; S32. If the password M2 is correct, then traverse the folder, confirm the identifiers of each encrypted file and each unencrypted file, and execute step S4; S4. The server sends a file type confirmation input interface to the local terminal; S41. Obtain the file type selection result sent by the local terminal, and based on the encrypted file identifiers and unencrypted file identifiers obtained in step S32 or step S22, determine whether the local terminal correctly responded to the requested file type.

[0031] S42. If the file type returned by the local terminal is the same as the file type corresponding to the file identifier obtained by the server, and the file type is an encrypted archive file; then send a password M2 input interface to the local terminal.

[0032] S43. If the password M2 is incorrect, the server generates a garbled file, sends the garbled file back to the local terminal, and then terminates the process.

[0033] S44. If the password M2 is correct, then proceed to step S5.

[0034] S45. If the file type returned by the local terminal is the same as the file type corresponding to the file identifier obtained by the server, and the file type is an unencrypted archive file; then proceed to step S5.

[0035] The server in question is an enterprise server.

[0036] S46. If the file type returned by the local terminal is different from the file type corresponding to the file identifier obtained by the server, then the process is terminated after returning an empty file to the local terminal.

[0037] S5. The server sends the file requested by the local terminal to the cloud gateway; The cloud gateway verifies whether the received file is the data requested by the local terminal; If the file received by the cloud gateway is the data requested by the local terminal, then step S6 is executed; If the file received by the cloud gateway is not the data requested by the local terminal, it sends a waiting buffer message to the local terminal and requests the data required by the local terminal directly from the server with the highest privilege, while sending an accessibility prompt to the server. For the requested data corresponding to the accessibility prompt, the server will no longer send any password or file type queries. Instead, the server will decrypt the requested data and send it back directly to the requesting client.

[0038] S6. The cloud gateway sends a file browsing mode selection interface to the local terminal; The local terminal can select either online browsing or download browsing; If the local terminal chooses to browse online, the cloud gateway will convert the file into an image format and add a watermark for the local terminal to browse online. If the local terminal chooses to download and browse, the cloud gateway records the local terminal's identity information and sends the file to the local terminal.

[0039] S7. The local terminal display device displays the file.

[0040] Furthermore, the folder stores multiple archive files, which are encrypted and / or unencrypted files.

[0041] Furthermore, the local terminal reports two file types: encrypted archive files and unencrypted archive files.

[0042] The present invention has the following beneficial effects: 1) It can provide multi-level account and password authentication from the enterprise's internal server to the terminal, which can enhance the security of file management. At the same time, the cloud gateway architecture can improve the data transmission speed, and the interaction between the cloud gateway and the enterprise server with the local terminal can form a multi-level management system, which facilitates troubleshooting.

[0043] 2) By setting up an architecture of enterprise server, cloud gateway and local terminal, the enterprise server and cloud gateway can interact with the local terminal at different stages of the file data request process. The cloud gateway can determine the permissions of the requester when forwarding request data, so as to provide different services based on different permissions. This can reduce the server load to a certain extent, ensure the security of file data and improve the system's work efficiency.

[0044] 3) Through the S4 configuration, the enterprise server can provide different files to the local terminal after determining whether the security verification at different levels is accurate. Specifically: if the file type returned by the local terminal is different from the file type corresponding to the file identifier obtained by the server, then an empty file is returned to the local terminal; if the password M2 is incorrect, then the server generates a garbled file and directly returns the garbled file to the local terminal. This method allows users or administrators to clearly identify at which level of security verification the problem occurred after seeing the file returned by the enterprise server and considering whether the enterprise server returned a file.

[0045] 4) By encrypting the folders storing archive data, encrypting only some archive files, and having the enterprise server and cloud gateway query the local terminal respectively, the security of archive data can be greatly improved. Furthermore, setting up online browsing and record download methods can effectively perform post-event statistics and queries.

[0046] 5) The present invention sets up a four-level security authentication to improve security. In the two-level security authentication process, even if the authentication fails, the enterprise server still provides the file to the local terminal. If the employee sends or uses the file without opening it, the other end can find out that the employee has not viewed or verified the downloaded data, which can assess the employee's work attitude to a certain extent.

[0047] The specific embodiments described above do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.

[0048] Those skilled in the art will understand that the modules or steps of the present invention described above can be implemented using general-purpose computer devices. Optionally, they can be implemented using computer-executable program code, thereby allowing them to be stored in a storage device for execution by a computer device, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. The present invention is not limited to any particular combination of hardware and software.

[0049] While the specific embodiments of the present invention have been described above in conjunction with the accompanying drawings, this is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art without creative effort based on the technical solutions of the present invention are still within the scope of protection of the present invention.

[0050] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or make equivalent substitutions for some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A digital archive encryption system, characterized in that, The system is capable of performing the following steps: S1. The local terminal sends a data request to the remote server via the cloud gateway; S2. Based on the data request, the server locates the folder where the data request is stored and determines whether the folder containing the file is an encrypted folder; S21. If the folder is an encrypted folder, the password M1 input interface is sent back to the local terminal via the cloud gateway, and step S3 is executed; S22. If the folder is an unencrypted folder, then traverse the folder, confirm the identifiers of each encrypted file and each unencrypted file, and execute step S4; S3. The server determines whether the password M1 is correct based on the password M1 fed back by the local terminal; S31. If the password M1 is incorrect, the requested data will not be provided to the user; S32. If the password M2 is correct, then traverse the folder, confirm the identifiers of each encrypted file and each unencrypted file, and execute step S4; S4. The server sends a file type confirmation input interface to the local terminal; S5. The server sends the file requested by the local terminal to the cloud gateway; S6. The cloud gateway sends a file browsing mode selection interface to the local terminal; S7. The local terminal display device displays the file.

2. The digital archive encryption system as described in claim 1, characterized in that, The folder stores multiple archive files, which are encrypted and / or unencrypted files.

3. The digital archive encryption system as described in claim 2, characterized in that, S41. Obtain the file type selection result sent by the local terminal, and based on the encrypted file identifiers and unencrypted file identifiers obtained in step S32 or step S22, determine whether the local terminal correctly responded to the requested file type.

4. A digital archive encryption system as described in claim 3, characterized in that, The local terminal reports two file types: encrypted archive files and unencrypted archive files.

5. A digital archive encryption system as described in claim 4, characterized in that, S42. If the file type returned by the local terminal is the same as the file type corresponding to the file identifier obtained by the server, and the file type is an encrypted archive file; then send a password M2 input interface to the local terminal.

6. A digital archive encryption system as described in claim 5, characterized in that, S43. If the password M2 is incorrect, the server generates a garbled file and then sends the garbled file directly to the local terminal.

7. A digital archive encryption system as described in claim 1, characterized in that, S44. If the password M2 is correct, then proceed to step S5.

8. A digital archive encryption system as described in claim 7, characterized in that, S45. If the file type returned by the local terminal is the same as the file type corresponding to the file identifier obtained by the server, and the file type is an unencrypted archive file; then proceed to step S5.

9. A digital archive encryption system as described in claim 8, characterized in that, The server in question is an enterprise server.

10. A digital archive encryption system as described in claim 9, characterized in that, S46. If the file type returned by the local terminal is different from the file type corresponding to the file identifier obtained by the server, then an empty file is returned to the local terminal.